Skip to Content

IT and Cyber Third Party Risk Assessor (Expert) - BNP Paribas Fortis

Customer: BNP Paribas Fortis Koningsstraat 97 1000 Brussels Belgium
Dates: 2026-10-01 — 2027-09-30
Arrangements: Hybrid - 50% on site & 50% homeworking
Apply before: 2026-10-09

Description

The Governance, Risk and Compliance team supports robust IT and Cyber Risk Management across BNP Paribas Fortis, with a strong focus on Third-Party Technology Risk Management. The expert assesses risks associated with intragroup and external suppliers and checks alignment with the bank’s IT and Information Security policies. A major focus is cloud-based services and the security, data-protection and resilience risks they create. The work spans supplier due diligence, contractual controls and ongoing risk oversight.

The role conducts comprehensive supplier assessments, reviews vulnerability and penetration-testing reports, and challenges IT and cybersecurity clauses in contracts. It also coordinates onsite audits, validates audit findings and follows remediation plans with suppliers. Critical IT and Cyber risks are escalated and followed through to timely resolution with internal stakeholders. Continuous monitoring includes security reports, incident responses and compliance attestations such as ISO 27001, SOC and NIST.

The expert leads ICT Risk and Cyber Committees and produces dashboards and synthetic reports for senior management. Collaboration is extensive, covering Cyber Defense, Security Architecture, Business and IT Continuity, Data Protection, Procurement and Legal teams. The assignment also contributes to evolving TPTRM frameworks, tools and methodologies in line with group standards, industry practice and regulatory changes. The expert develops assessment templates, audit guidelines and reporting standards for expert and non-expert audiences.

Top Reasons to Apply
Strategic cyber risk
★★★★★
Cloud security exposure
★★★★★
Senior stakeholder influence
★★★★★
Framework development impact
★★★★★
Cross-functional collaboration
★★★★★
Responsibilities
Conduct supplier risk assessments
Assess cloud security solutions
Review vulnerability testing reports
Negotiate cybersecurity contract clauses
Collaborate on contractual mitigations
Pilot onsite cyber audits
Review IT audit reports
Track supplier remediation plans
Must Have
10+ years security experience
IT Cyber Risk Management
Third-party risk assessments
Cloud security expertise
Supplier security assessments
Application security experience
Vulnerability management experience
Penetration testing experience
Nice to Have
Dutch fluent proficiency
Security certifications preferred
Control frameworks knowledge
Audit methodologies knowledge
ServiceNow GRC familiarity

Detailed Responsibilities and Skills

Additional Responsibilities

  • Escalate critical cyber risks
  • Monitor third-party security posture
  • Lead ICT risk committees
  • Develop ICT risk dashboards
  • Align cyber threat intelligence
  • Assess technical security controls
  • Ensure supplier continuity resilience
  • Validate privacy regulation compliance
  • Integrate procurement risk considerations
  • Evolve TPTRM risk frameworks
  • Develop risk assessment templates
  • Refine audit reporting standards

General skills

  • Master degree in IT, Cybersecurity, Risk Management, or equivalent by experience.
  • 10+ years of professional experience in information security.
  • Professional experience in Financial Services, particularly in large corporate environments.
  • Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
  • Experience in process design and business analysis, particularly in IT and security risk management.
  • Experience delivering presentations and training to stakeholders on risk-related topics.
  • French: fluent and mandatory.
  • English: fluent and mandatory.
  • Dutch: fluent; the vacancy does not explicitly mark it mandatory.
  • Strong analytical and synthesis skills, with the ability to distill complex technical risks into clear, actionable management insights.
  • Excellent communication and influencing skills with technical experts, business stakeholders, and external suppliers.
  • Autonomous, proactive, and results-driven working style.
  • Structured and methodical approach.
  • Ability to manage multiple priorities in a dynamic, multicultural environment.
  • Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
  • Ability to capture and adapt to stakeholder expectations while respecting processes in place.
  • Ability to mentor and coach people.
  • Security certifications such as CISSP, CISM, CIPP, or CCSK are optional.

Technical skills

  • 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
  • Experience conducting third-party IT and security assessments, including risk evaluations for suppliers and vendors.
  • Experience with application security.
  • Experience with vulnerability management.
  • Experience with penetration testing.
  • Experience with audit methodologies and standards including ISO 27001, SOC 2, NIST, and OWASP.
  • Proficiency in Information Security and Risk Management frameworks, including ISO 27001, SOC, NIST, and OWASP.
  • Strong IT background with exposure to operational and security risk management.
  • Knowledge of control frameworks and audit methodologies is preferable.
  • Familiarity with the GRC tool ServiceNow is preferable.

Tools

  • Cloud environments and service models: SaaS, IaaS, PaaS; the mission context also references HSP and AWS.
  • ServiceNow GRC familiarity is preferable.
  • Security and audit standards/frameworks referenced: ISO 27001, SOC/SOC 2, NIST, OWASP.
  • ICT risk dashboards, assessment templates, audit guidelines, and reporting standards.